Robin H. Johnson wrote:
This patch adds a new configuration option 'tls_before_auth', that when set,
does not offer AUTH until the connection has been secured. This helps to
prevent password disclosures with SASL LOGIN/PLAIN mechanisms.

Applied, thanks! You provided a patch to README (good, I don't remember to do that piece) but we also include a sample configuration in config.sample, which I created before applying.

I also committed your "SSL in header" patch at the same time.

Thanks

John

Reply via email to